Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

App only requires Touch/Face ID for the initial opening #123

Open
1 task done
spuk- opened this issue Jun 27, 2024 · 2 comments
Open
1 task done

App only requires Touch/Face ID for the initial opening #123

spuk- opened this issue Jun 27, 2024 · 2 comments
Labels
bug Something isn't working

Comments

@spuk-
Copy link

spuk- commented Jun 27, 2024

Steps To Reproduce

  1. Go to the app settings tab
  2. Enable "Unlock with Touch ID"
  3. Press the home button to exit Authenticator
  4. Tap on the Authenticator app to enter it again without requiring Touch ID

Expected Result

The app should require Touch ID to be opened.

Actual Result

The app is opened without requiring Touch ID.

The app only requires Touch ID when the app is reopened after being closed (i.e. Double press the home button for the apps list and push it off the screen for closing it).

Screenshots or Videos

No response

Additional Context

No response

Build Version

2024.6.1

Environment Details

  • Device: iPhone SE 2022
  • iOS: 17.5.1

Issue Tracking Info

  • I understand that work is tracked outside of Github. A PR will be linked to this issue should one be opened to address it, but Bitwarden doesn't use fields like "assigned", "milestone", or "project" to track progress.
@spuk- spuk- added the bug Something isn't working label Jun 27, 2024
@RobertD502
Copy link

I'd like to add that the same behavior is seen with Face ID.

Version: 2024.6.1 (45)

@spuk- spuk- changed the title App only requires Touch ID for the initial opening App only requires Touch/Face ID for the initial opening Jul 1, 2024
@samholmes
Copy link

I just submitted this feature request to support. I'd like to further add this request:

  1. Touch/Face ID is required to view a raw TOTP key.
  2. Touch/Face ID is required to export data

This further limits attackers from somehow getting access to a user's TOTP keys discretely if the user were to make the mistake of leaving the Authenticator app open and unlocked. An attacker couldn't sweep a user's TOPT data discretely with the intention to brute-force their accounts later on. The worst an attack could do in that event is attempt to brute-force their individual accounts in the moment they have access to opened app.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants